PROBABLYPWNED
Home/Tag/Ai Security

Ai Security

58 articles tagged with "Ai Security"

Agentjacking Hijacks AI Coding Agents via Sentry MCP Injection
Vulnerabilities4 min read

Agentjacking Hijacks AI Coding Agents via Sentry MCP Injection

Researchers at Tenet Security discovered Agentjacking, an attack that tricks AI coding assistants like Claude Code and Cursor into executing arbitrary code through malicious Sentry error events.

Vulnerability DeskJun 14, 2026
AI Browsers Create New Attack Surface for Prompt Injection
Security Guides5 min read

AI Browsers Create New Attack Surface for Prompt Injection

The 2026 State of Browser Security Report reveals AI-integrated browsers and agentic copilots face systemic prompt injection risks that may never be fully solved. Here's what enterprises need to know.

ProbablyPwned Editorial TeamJun 2, 2026
Flowise One-Click RCE — Import a Chatflow, Lose Your Server
Vulnerabilities3 min read

Flowise One-Click RCE — Import a Chatflow, Lose Your Server

CVE-2026-40933 (CVSS 9.9) allows attackers to compromise self-hosted Flowise AI agent builders by tricking users into importing a malicious chatflow. The payload executes during import without user action.

Vulnerability DeskMay 31, 2026
ChatGPhish Turns ChatGPT Web Summaries Into Phishing Delivery
Vulnerabilities4 min read

ChatGPhish Turns ChatGPT Web Summaries Into Phishing Delivery

Researchers discover ChatGPT's Markdown rendering trusts attacker-controlled content from summarized pages, enabling phishing URLs, IP exfiltration, and fake security alerts inside the AI interface.

Vulnerability DeskMay 31, 2026
MuddyWater Exploits Langflow Flaw for Initial Access
Vulnerabilities3 min read

MuddyWater Exploits Langflow Flaw for Initial Access

CISA adds CVE-2025-34291 to KEV after Iranian APT MuddyWater weaponizes the CORS/CSRF chain for account takeover and RCE. CVSS 9.4 flaw requires only a malicious link click.

Vulnerability DeskMay 24, 2026
24 Zero-Days Fall on Day One of Pwn2Own Berlin 2026
Vulnerabilities4 min read

24 Zero-Days Fall on Day One of Pwn2Own Berlin 2026

Security researchers exploited Windows 11, Microsoft Edge, Red Hat Linux, and multiple AI platforms on the first day of Pwn2Own Berlin 2026, earning $523,000 for 24 unique zero-day vulnerabilities.

Vulnerability DeskMay 14, 2026
Google Catches First AI-Generated Zero-Day Exploit in the Wild
Threat Intelligence4 min read

Google Catches First AI-Generated Zero-Day Exploit in the Wild

Google's Threat Intelligence Group identifies a criminal group using an LLM-generated exploit to bypass 2FA in a web admin tool—marking the first confirmed AI-built zero-day in active use.

Threat Intel DeskMay 11, 2026
One Researcher, Four Critical RCE Bugs in AI Frameworks
Vulnerabilities5 min read

One Researcher, Four Critical RCE Bugs in AI Frameworks

Security researcher Valentin Lobstein discovers CVSS 9.8 pickle deserialization vulnerabilities in LeRobot, ktransformers, and LightLLM. ML frameworks using pickle for network serialization create widespread attack surface.

Vulnerability DeskApr 26, 2026
LMDeploy SSRF Exploited 12 Hours After Disclosure
Vulnerabilities4 min read

LMDeploy SSRF Exploited 12 Hours After Disclosure

CVE-2026-33626 in LMDeploy AI toolkit was weaponized within 12 hours of publication, targeting AWS credentials and internal services. Patch to v0.12.3 immediately.

Vulnerability DeskApr 24, 2026
PraisonAI Sandbox Bypass Scores Perfect CVSS 10
Vulnerabilities3 min read

PraisonAI Sandbox Bypass Scores Perfect CVSS 10

CVE-2026-34938 lets attackers escape PraisonAI's three-layer Python sandbox to execute arbitrary OS commands. CVSS 10 — patch to version 1.5.90 immediately.

Vulnerability DeskApr 4, 2026
LangChain Flaws Expose Files, Secrets, and Databases
Vulnerabilities3 min read

LangChain Flaws Expose Files, Secrets, and Databases

Three vulnerabilities in LangChain and LangGraph expose filesystems, environment secrets, and conversation histories. CVE-2026-34070 enables path traversal. Patches available now.

Vulnerability DeskMar 28, 2026
Langflow RCE Exploited Within 20 Hours of Disclosure
Vulnerabilities4 min read

Langflow RCE Exploited Within 20 Hours of Disclosure

CVE-2026-33017 (CVSS 9.3) lets attackers execute arbitrary Python code on Langflow AI pipelines without authentication. Exploitation began before any PoC existed.

Vulnerability DeskMar 21, 2026
WeKnora AI Framework Hit with Twin CVSS 9.9 RCE Flaws
Vulnerabilities4 min read

WeKnora AI Framework Hit with Twin CVSS 9.9 RCE Flaws

Critical command injection and SQL bypass vulnerabilities in Tencent's WeKnora LLM framework allow unauthenticated RCE. Patch to versions 0.2.10 and 0.2.12 now.

Vulnerability DeskMar 8, 2026
Cisco AI Security Report: 83% Want Agents, 29% Ready
Announcements4 min read

Cisco AI Security Report: 83% Want Agents, 29% Ready

Cisco's State of AI Security 2026 report reveals a dangerous gap between agentic AI adoption ambitions and enterprise security readiness. Here's what the threat landscape looks like.

ProbablyPwned Editorial TeamFeb 19, 2026
How to Detect Deepfakes: Signs, Tools, and Protection
Security Guides9 min read

How to Detect Deepfakes: Signs, Tools, and Protection

Learn how to detect deepfakes with visual clues, audio patterns, and authentication methods. Covers detection signs, AI tools, and practical defense strategies.

ProbablyPwned Editorial TeamFeb 11, 2026